Everyone tests the email field for formatting. Almost no one tests it for XSS.
That blind spot let Synack Red Team researcher Salman Khan turn a routine account settings field into a full attack chain. The email spec allows a "+" for subaddress tagging, and Salman used that trick to slip an XSS payload past validation and store it, unencoded, in his own profile. Then he sent a clean, normal looking invitation to a test account, no payload in the email itself, no login required to open it. The page rendered his poisoned profile the moment it loaded, and the exploit fired on mouseover.
Three separate layers of validation missed it. Read how: hubs.ly/Q04vywJb0
#ExploitsExplained #PenTesting #XSS #SynackRedTeam
Aug 27, 2026 · 4:03 PM UTC
3
8
76
4,923




